FDA Wants Abbott Cybersecurity Fixes
Attorneys Cameron Abbott and Giles Whittaker (K&L Gates) say FDA is threatening legal action against Abbott if the company doesn’t address safety and security issues in implanted cardiac devices sold by its recently acquired St. Jude Medical unit. Writing in an online blog post, the two say an agency Warning Letter gave the company 15 days to submit a plan to address errors in the products’ design that could allow hackers to tamper with the settings and drain the device’s batteries, which were thought to have contributed to the cause of a death.
“Many of the cybersecurity concerns first came to light after medical device security research firm MedSec submitted a report outlining a variety of alleged security flaws in St. Jude Medical products to investment firm Muddy Waters Research,” the attorneys write. The research firm publicly announced the product design failures while short-selling St. Jude Medical stock to capitalize on the expected market response, they say.
The attorneys write that companies that don’t make cybersecurity considerations central to their business model risk having their inadequacies called out in a public forum as well as facing liability litigation.